Help Center/ Organizations/ User Guide/ Managing NCPs/ Enabling or Disabling the NCP Type
Updated on 2026-08-25 GMT+08:00

Enabling or Disabling the NCP Type

Enabling the NCP Type

Before you create and attach an NCP to OUs and accounts, you have to enable the NCP type using the organization's management account. After the NCP type is enabled, the organization automatically attaches the NCPFullAccess policy (allowing all operations by default) to all OUs and accounts.

  1. Log in to the Organizations console as an organization administrator or using the management account.
  2. On the Policies page, click Enable in the Operation column of the network control policies.
  3. Click OK.

    Figure 1 Enabling the NCP type

The default NCPFullAccess policy cannot be detached.

Disabling the NCP Type

If you no longer want to use NCPs to manage permissions for your organization, you can disable the NCP type using the organization's management account.

  • After the NCP type is disabled in an organization, all NCPs are automatically detached from all OUs and accounts in the organization. However, the NCPs are not deleted.
  • If the NCP type is disabled and then re-enabled, all entities in the organization will revert to being attached only to NCPFullAccess. Attachments between entities and other NCPs will be lost; if you need to restore them, you must re-attach them manually.
  • If the NCP type is disabled but some NCPs are not deleted, the organization cannot be deleted.
  1. Log in to the Organizations console as an organization administrator or using the management account.
  2. On the Policies page, click Disable in the Operation column of the network control policies.

    Figure 2 Disabling the NCP type

  3. Click OK in the displayed dialog box.